AtlSecCon 2022 has ended
Back To Schedule
Friday, April 8 • 15:00 - 15:45
Hacking JWT

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

JWTs are an important part of how modern APIs are used, they assert your identify to the application. You will see them in SOAP, REST, and GraphQL. Many decisions about authorization and access are based on the claims contained within the JWT. If there are vulnerabilities within the framework used to create them, or in implementation decisions, the impact can be high. In this talk , I will discuss how JWTs are generated and used. Security issues can include information disclosure, authentication bypass, authorization control bypass, password cracking, JWT reuse, algorithms such as None, and algorithm exchange. I will demonstrate the None algorithm attack, cracking the secret key used to sign the JWT, and algorithm exchange.

avatar for Adrien de Beaupre

Adrien de Beaupre

Senior Cyber/Information Security Consultant, Penetration Tester, Principal SANS Instructor and course author
Today, in addition to being a prolific SANS instructor and course author, Adrien is an independent penetration tester in both the Government and private sectors around the world.A sought-after instructor known for his engaging, straight-forward style, professionalism, and real-world... Read More →

Friday April 8, 2022 15:00 - 15:45 ADT
Track 2 - Summit Suite - Room 603/604